PT-2026-5078 · WordPress · Registrationmagic

Md. Moniruzzaman Prodhan

+1

·

Published

2026-01-28

·

Updated

2026-01-28

·

CVE-2026-1054

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions RegistrationMagic plugin for WordPress versions through 6.0.7.4
Description The RegistrationMagic plugin for WordPress is affected by a missing authorization issue. Specifically, nonce verification and capability checks are absent in the rm set otp AJAX action handler. This allows unauthenticated attackers to modify plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.
Recommendations Update to version 6.0.7.5 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1054

Affected Products

Registrationmagic